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Response to WG Consultation on Vessel Monitoring Systems for fishing 
boats in Wales 


Background 


The Information Commissioner (the Commissioner) has responsibility for 
promoting and enforcing the EU General Data Protection Regulation (GDPR), the 
UK Data Protection Act 2018 (DPA 2018) and other information rights legislation. 


The Commissioner is independent of government and upholds information rights 
in the public interest, promoting openness by public bodies and data privacy for 
individuals. The Commissioner does this by providing guidance to individuals and 
organisations, solving problems where she can, and taking appropriate action 
where the law is broken. 


Vessel Monitoring Systems (VMS) and Personal Data 


The Commissioner believes it is likely that any proposed VMS will process data 
that falls within the GDPR definition of ‘personal data’. That definition is set out 
in Article 4 of GDPR as follows: 


“Personal data’ means any information relating to an identified or 
identifiable natural person (‘data subject’); an identifiable natural person is 
one who can be identified, directly or indirectly, in particular by reference 
to an identifier such as a name, an identification number, location data, an 
online identifier or to one or more factors specific to the physical, 
physiological, genetic, mental, economic, cultural or social identity of that 
natural person”. 


Recital (30) further explains: 


“Natural persons may be associated with online identifiers provided by their 
devices, applications, tools and protocols, such as internet protocol 
addresses, cookie identifiers or other identifiers such as radio frequency 
identification tags”. 


We welcome correspondence in Welsh Information Commissioner's Office (Head Office) 

and this will not lead to any delays. Swyddfa’r Comisiynydd Gwybodaeth (Prif Swyddfa) 
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF 
T. 0303 123 1113 F. 01625 524510 


İCO. 


Information Commissioner’s Office 
Swyddfa'r Comisiynydd Gwybodaeth 


Statutory Requirement to Consult I CO 


Under Article 36(4) of GDPR, Member States are required to “consult the 
supervisory authority during preparation of a proposal for a legislative measure 
to be adopted by a national parliament, or of a regulatory measure based on 
such a legislative measure, which relates to processing”. Guidance on the 
application of Article 36(4) has been published by DCMS. Paragraph 2.10 of the 
guidance states “Article 36(4) applies directly to the UK, and therefore the 
requirements of this provision also apply to legislative and statutory measures 
adopted by the devolved legislatures”. 


The matters covered within this public consultation appear to fall within scope of 
the Article 36(4) requirement and therefore the Welsh Government should 
consult directly with the Commissioner as laid out in the DCMS Guidance. 

The letter is copied to the Data Protection Officer for Welsh Government. We 


recommend that in taking forward the issues raised in this letter you liaise with 
the Welsh Government’s in house data protection team. 
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David Teague 
Regional Manager (Wales) 
Information Commissioner’s Office 


cc: DataProtectionOfficer@gov.wales 
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